CVE-2008-7267
SiteEngine 5.x - SQL Injection via Announcements.php id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-7267. PoCs published by xuanmumu, xy7.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in SiteEngine 5.0 via the 'id' parameter in announcements.php. The PoC uses a UNION-based SQLi to extract database information, such as the current user.
Description
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
This exploit demonstrates an SQL injection vulnerability in SiteEngine 5.0 via the 'id' parameter in announcements.php. The PoC uses a UNION-based SQLi to extract database information, such as the current user.
The exploit demonstrates multiple vulnerabilities in SiteEngine 5.x, including SQL injection via improper use of the intval function, URI redirection, and information disclosure. The SQL injection POC bypasses parameter validation by appending non-numeric characters to the input.